Key and flexible public key signature conversion method and device based on threshold secret sharing, equipment and medium

Through threshold secret sharing technology, the signature private key and public key are generated and transformed with the participation of multiple parties, and a single point of failure risk is solved. It is suitable for multi-party distributed scenarios, improving the robustness and robustness of the signature private key.

CN120342598APending Publication Date: 2025-07-18CETC CYBERSPACE SECURITY TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510538609.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-27
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

In the existing flexible public key signature algorithm, the signed private key is held by a single party, which increases the risk of single point of failure and is not suitable for multi-party distributed application scenarios. How to improve its robustness and robustness.

Method used

The method based on threshold secret sharing is adopted, and the system parameters, private keys and public keys are generated through the collaborative calculation of participants, and random polynomials are accumulated during the signature and key transformation process to ensure the threshold characteristics and are suitable for multi-party distributed scenarios.

Benefits of technology

It improves the robustness and robustness of flexible public key signature private keys, is suitable for multi-party distributed application scenarios, provides flexible permission control functions, and reduces computing and communication overhead.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342598A_ABST
    Figure CN120342598A_ABST
Patent Text Reader

Abstract

The invention discloses a secret key and flexible public key signature conversion method and device based on threshold secret sharing, equipment and a medium, and relates to the technical field of information security. Initialization parameters are calculated to obtain system sub-parameters; performing private key share calculation on the system parameters to generate a private key and a public key; when the signature generation information is obtained, a sub-signature is generated, if the type of the participant is non-signature generation, the sub-signature is sent to the participant whose participant type is signature generation, and a signature is generated; when a secret key transformation instruction is obtained, finite field polynomials returned by other participants are accumulated, a new private key share is calculated, the new private key share is sent to a transformation system, and a new private key and a new public key are generated; and when the signature conversion instruction is obtained, the new sub-signature is generated, and if the participant type is non-signature generation, the new sub-signature is sent to the participant whose participant type is signature generation, and the new signature is generated, so that the robustness and robustness of the flexible public key signature and the private key are improved, and the method is suitable for a multi-party distributed application scene.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and particularly relates to a key and flexible public key signature transformation method, device, equipment and medium based on threshold secret sharing. Background Art

[0002] In SFPK (Signatures with flexible public key), after generating a signature using a pair of public and private keys, the public key and the signature value can be changed, and at the same time, the changed signature can be verified using the changed public key, that is, signing a signature once using a public key is equivalent to generating all signatures of the equivalence class of the public key, which can play a role in hiding the specific signature public key. The flexible public key signature algorithm has a mature design method and is often used in the design of privacy protection protocols such as anonymous credentials. In the existing flexible public key signature algorithm, the signature private key is only held and saved by the signer alone, which increases the risk of single point of failure and is not suitable for multi-party distributed application scenarios.

[0003] As can be seen from the above, how to improve the robustness and robustness of the flexible public key signature private key, threshold the single-party signature private key, and apply it to multi-party distributed application scenarios is a problem to be solved in this field. Summary of the Invention

[0004] In view of this, the purpose of the present invention is to provide a key and flexible public key signature transformation method, device, equipment and medium based on threshold secret sharing, which can improve the robustness and robustness of the flexible public key signature private key, threshold the single-party signature private key, and apply it to multi-party distributed application scenarios. The specific scheme is as follows:

[0005] In the first aspect, the present application discloses a key and flexible public key signature transformation method based on threshold secret sharing, which is applied to any participant in the transformation system, including:

[0006] Obtain the initialization parameters sent by the transformation system, calculate the system sub-parameters from the initialization parameters, and send the system sub-parameters to the transformation system so that the transformation system can use the threshold secret sharing scheme and generate system parameters based on all the system sub-parameters;

[0007] Calculate the private key shares from the system parameters, and send the private key shares to the transformation system so that the transformation system can generate a private key and the corresponding public key based on all the private key shares;

[0008] When the signature generation information is obtained, a sub-signature is generated, and the participant type of itself is judged. If the participant type of itself is non-signature generation, the sub-signature is sent to the participant with the participant type of signature generation, so that the participant with the participant type of signature generation generates a signature based on all the sub-signatures;

[0009] When the key transformation instruction is obtained, a random polynomial is generated, and the random polynomial is sent to other participants except itself, so that the other participants calculate a finite field polynomial based on the random polynomial, accumulate the finite field polynomials returned by the other participants and calculate a new private key share, and send the new private key share to the transformation system, so that the transformation system generates a new private key and the corresponding new public key based on all the new private key shares;

[0010] When the signature transformation instruction is obtained, a new sub-signature is generated based on the original signature corresponding to the signature transformation instruction, and the participant type of itself is judged. If the participant type of itself is non-signature generation, the new sub-signature is sent to the participant with the participant type of signature generation, so that the participant with the participant type of signature generation generates a new signature based on all the new sub-signatures.

[0011] Optionally, obtaining the initialization parameters sent by the transformation system and calculating the initialization parameters to obtain system sub-parameters includes:

[0012] Obtaining the initialization parameters including large prime numbers, cyclic groups and bilinear pair mappings generated by the transformation system based on security parameters; the cyclic groups include a first cyclic group, a second cyclic group and a third cyclic group;

[0013] Selecting random system calculation elements, and calculating the random system calculation elements, the first generator corresponding to the first cyclic group, and the second generator corresponding to the second cyclic group to obtain a first system sub-parameter and a second system sub-parameter.

[0014] Optionally, the first system sub-parameter is:

[0015] ;

[0016] Where is a random system calculation element, and , , is a non-zero integer domain, n is the number of participants, is the first generator corresponding to the first cyclic group, is the first system sub-parameter;

[0017] The second system sub-parameter is:

[0018] ;

[0019] Wherein, is the second generator corresponding to the second cyclic group, is the second system sub-parameter;

[0020] Correspondingly, the system parameters include a first system parameter and a second system parameter;

[0021] The first system parameter is:

[0022] ;

[0023] Wherein, is the product symbol;

[0024] The second system parameter is:

[0025] .

[0026] Optionally, the calculating the private key share for the system parameters includes:

[0027] Selecting a random polynomial element, and calculating a first private key share polynomial and a second private key share polynomial based on the random polynomial element;

[0028] Sending the second private key share polynomial to other parties except itself, and obtaining a third private key share polynomial sent by the other parties;

[0029] Calculating the private key share by using the first private key share polynomial and the third private key share polynomial.

[0030] Optionally, when obtaining the signature generation information, generating a sub-signature and judging the type of its own participating party includes:

[0031] When obtaining the signature generation information, selecting a random sub-signature element, and generating a sub-signature by using the random sub-signature element, the private key share, the Lagrange interpolation coefficient, and the initialization parameter;

[0032] Judging the type of its own participating party. If the type of its own participating party is signature generation, directly obtaining the sub-signatures sent by other parties except itself, and generating a signature based on all the sub-signatures.

[0033] Optionally, after generating the signature based on all the sub-signatures, it further includes:

[0034] Sending the signature to the transformation system so that the transformation system presents the signature to the client for signature verification;

[0035] After obtaining the instruction returned by the client for characterizing that the signature verification is passed, start a thread for obtaining the signature transformation instruction.

[0036] Optionally, the sending the random polynomial to other parties except itself, so that the other parties calculate a finite field polynomial based on the random polynomial, and performing accumulation and new private key share calculation on the finite field polynomials returned by the other parties includes:

[0037] Select a random finite field element, generate an initial random polynomial over the finite field based on the random finite field element, calculate a random polynomial using the initial random polynomial, and send the calculated random polynomial to other parties except itself, so that the other parties calculate a finite field polynomial based on the random polynomial;

[0038] Obtain each of the finite field polynomials returned by other parties, accumulate all the finite field polynomials to obtain an accumulated value;

[0039] Perform new private key share calculation on the accumulated value and the private key share corresponding to itself to obtain a new private key share.

[0040] In a second aspect, the present application discloses a key and flexible public key signature transformation device based on threshold secret sharing, which is applied to any party in a transformation system, and includes:

[0041] A parameter generation module, configured to obtain initialization parameters sent by the transformation system, calculate system sub-parameters from the initialization parameters, and send the system sub-parameters to the transformation system, so that the transformation system uses a threshold secret sharing scheme and generates system parameters based on all the system sub-parameters;

[0042] A calculation module, configured to calculate private key shares from the system parameters, and send the private key shares to the transformation system, so that the transformation system generates a private key and a corresponding public key based on all the private key shares;

[0043] A signature generation module, configured to generate a sub-signature when obtaining signature generation information, determine its own party type, and if its own party type is non-signature generation, send the sub-signature to a party with a signature generation party type, so that the party with a signature generation party type generates a signature based on all the sub-signatures;

[0044] A key transformation module, configured to generate a random polynomial when a key transformation instruction is obtained, send the random polynomial to other parties except itself, so that the other parties calculate a finite field polynomial based on the random polynomial, accumulate the finite field polynomials returned by the other parties and calculate a new private key share, and send the new private key share to the transformation system, so that the transformation system generates a new private key and a corresponding new public key based on all the new private key shares;

[0045] A signature transformation module, configured to generate a new sub-signature based on an original signature corresponding to the signature transformation instruction when a signature transformation instruction is obtained, determine its own party type, and if its own party type is non-signature generation, send the new sub-signature to a party whose party type is signature generation, so that the party whose party type is signature generation generates a new signature based on all the new sub-signatures.

[0046] Thirdly, the present application discloses an electronic device, including:

[0047] A memory, configured to store a computer program;

[0048] A processor, configured to execute the computer program to implement the foregoing key and flexible public key signature transformation method based on threshold secret sharing.

[0049] Fourthly, the present application discloses a computer storage medium, configured to store a computer program; wherein, when the computer program is executed by a processor, the steps of the foregoing disclosed key and flexible public key signature transformation method based on threshold secret sharing are implemented.

[0050] It can be seen that the present application provides a key and flexible public key signature transformation method based on threshold secret sharing, including obtaining initialization parameters sent by a transformation system, calculating the initialization parameters to obtain system sub-parameters, and sending the system sub-parameters to the transformation system so that the transformation system uses a threshold secret sharing scheme and generates system parameters based on all the system sub-parameters; calculating private key shares for the system parameters and sending the private key shares to the transformation system so that the transformation system generates a private key and a corresponding public key based on all the private key shares; when signature generation information is obtained, generating a sub-signature, determining its own participant type, and if its own participant type is non-signature generation, sending the sub-signature to a participant with a participant type of signature generation so that the participant with a participant type of signature generation generates a signature based on all the sub-signatures; when a key transformation instruction is obtained, generating a random polynomial and sending the random polynomial to other participants except itself so that the other participants calculate a finite field polynomial based on the random polynomial, performing accumulation and new private key share calculation on the finite field polynomials returned by the other participants, and sending the new private key shares to the transformation system so that the transformation system generates a new private key and a corresponding new public key based on all the new private key shares; when a signature transformation instruction is obtained, generating a new sub-signature based on the original signature corresponding to the signature transformation instruction, determining its own participant type, and if its own participant type is non-signature generation, sending the new sub-signature to a participant with a participant type of signature generation so that the participant with a participant type of signature generation generates a new signature based on all the new sub-signatures.This application calculates the initialization parameters sent by the transformation system to obtain system sub-parameters, generates system parameters, private key shares, private keys, and corresponding public keys based on the threshold secret sharing scheme, thresholds the single-party signature private key, generates sub-signatures during the signature generation process, and then generates signatures. There is no need for each participating party to communicate interactively, and the communication overhead is low. During the key transformation process, a random polynomial is generated, the random polynomial is sent to other participating parties except itself, and the finite field polynomials returned by other participating parties are accumulated and new private key shares are calculated, so that the transformation system can generate a new private key and corresponding new public key based on all the new private key shares, ensuring that the transformed key still satisfies the threshold property. During the signature transformation process, new sub-signatures are generated based on the original signature corresponding to the signature transformation instruction, and the type of the participating party itself is judged. If the type of the participating party itself is non-signature generation, the new sub-signatures are sent to the participating parties whose type is signature generation, so that the participating parties whose type is signature generation can generate new signatures based on all the new sub-signatures. It can be applied to distributed scenarios, provide flexible permission control functions, and can improve the robustness and robustness of flexible public key signature private keys. This application is applied to any participating party in the transformation system, does not rely on components with high overhead such as homomorphic encryption, and only requires threshold secret sharing as a basic tool, with low computational overhead. Description of the Drawings

[0051] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.

[0052] Figure 1 Flowchart of a key and flexible public key signature transformation method based on threshold secret sharing disclosed in this application;

[0053] Figure 2 Structural schematic diagram of a key and flexible public key signature transformation device based on threshold secret sharing disclosed in this application;

[0054] Figure 3 Structural diagram of an electronic device provided by this application. Detailed Embodiments

[0055] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0056] In SFPK, after generating a signature using a pair of public and private keys, the public key and the signature value can be changed, while ensuring that the changed signature can be verified using the changed public key. That is, signing a signature once with a public key is equivalent to generating all signatures for the equivalence class of that public key, which can hide the specific public key used for signing. The flexible public key signature algorithm has a mature design method and is often used in the design of privacy protection protocols such as anonymous credentials. In existing flexible public key signature algorithms, the signature private key is only held and stored by the signer alone, increasing the risk of single point of failure and being unsuitable for multi-party distributed application scenarios. As can be seen from the above, how to improve the robustness and resilience of the flexible public key signature private key, threshold the single-party signature private key, and make it applicable to multi-party distributed application scenarios is an issue to be solved in this field.

[0057] See Figure 1 As shown, an embodiment of the present invention discloses a key and flexible public key signature transformation method based on threshold secret sharing, which is applied to any participating party in a transformation system and specifically may include:

[0058] Step S11: Obtain the initialization parameters sent by the transformation system, calculate the system sub-parameters for the initialization parameters, and send the system sub-parameters to the transformation system so that the transformation system can generate system parameters using the threshold secret sharing scheme and based on all the system sub-parameters.

[0059] In this embodiment, the process of calculating the system sub-parameters is as follows: Obtain the initialization parameters sent by the transformation system based on security parameters, including large prime numbers, cyclic groups, and bilinear pairings; the cyclic group includes a first cyclic group, a second cyclic group, and a third cyclic group; select random system calculation elements, and calculate the random system calculation elements, the first generator corresponding to the first cyclic group, and the second generator corresponding to the second cyclic group to obtain a first system sub-parameter and a second system sub-parameter; the first system sub-parameter is:

[0060] ;

[0061] Wherein, is a random system calculation element, and , , is a non-zero integer domain, n is the number of participating parties, is the first generator corresponding to the first cyclic group, is the first system sub-parameter;

[0062] The second system sub-parameter is:

[0063] ;

[0064] Among them, is the second generator corresponding to the second cyclic group, is the second system sub-parameter;

[0065] Correspondingly, the system parameters include a first system parameter and a second system parameter;

[0066] The first system parameter is:

[0067] ;

[0068] Among them, is the product symbol;

[0069] The second system parameter is:

[0070] .

[0071] Specifically, obtain the initialization parameters e including large prime number p, cyclic group generated based on the security parameter and bilinear pair mapping sent by the transformation system, is a bilinear pair; the cyclic group includes a first cyclic group , a second cyclic group and a third cyclic group , with order p; select a random system calculation element , calculate the random system calculation element and the first generator corresponding to , and the second generator corresponding to to obtain the first system sub-parameter and the second system sub-parameter as ; among them, represents the y-th power of , and the rest of the symbols are similar.

[0072] Assume that the number of participating parties is n, which are respectively , and the corresponding identity identifiers are respectively recorded as , the threshold is , each participating party , , calculates its own corresponding system sub-parameter, and then sends the system sub-parameter to the transformation system, so that the transformation system can use the threshold secret sharing scheme and generate system parameters based on all the system sub-parameters.

[0073] Step S12: Calculate the private key shares for the system parameters, and send the private key shares to the transformation system, so that the transformation system can generate a private key and the corresponding public key based on all the private key shares.

[0074] In this embodiment, random polynomial elements are selected, and a first private key share polynomial and a second private key share polynomial are calculated based on the random polynomial elements; the second private key share polynomial is sent to other participants except itself, and a third private key share polynomial sent by the other participants is obtained; the private key share is calculated using the first private key share polynomial and the third private key share polynomial, and the private key share is sent to the transformation system so that the transformation system generates a private key and a corresponding public key based on all the private key shares.

[0075] Specifically, for all , the participant selects random polynomial elements to generate a random polynomial over the finite field ; where is a random number in , ; t is the degree of the polynomial ; the value of the polynomial at the variable is calculated and is sent to the participant ; the participant announces ; the participant calculates , calculates the private key share , calculates and announces the public key .

[0076] For example, there are three participants. The first participant selects random polynomial elements , then calculates the first private key share polynomial and the second private key share polynomial , then sends the second private key share polynomial to the second participant and the third participant respectively. The second participant and the third participant then generate the corresponding third private key share polynomials , , then calculate the private key share. All three participants perform the above steps. Finally, the private key shares sent by the three participants are obtained. After the transformation system obtains all the private key shares, it generates a private key and a corresponding public key.

[0077] Step S13: When signature generation information is obtained, a sub-signature is generated, and the participant type of itself is determined. If the participant type of itself is non-signature generation, the sub-signature is sent to the participant whose participant type is signature generation so that the participant whose participant type is signature generation generates a signature based on all the sub-signatures.

[0078] In this embodiment, when the signature generation information is obtained, a random sub-signature element is selected, and the sub-signature is generated by using the random sub-signature element, the private key share, the Lagrange interpolation coefficient, and the initialization parameter; the type of the participating party itself is judged. If the type of the participating party itself is signature generation, the sub-signatures sent by other participating parties except itself are directly obtained, and the signature is generated based on all the sub-signatures; if the type of the participating party itself is non-signature generation, the sub-signature is sent to the participating party whose type of the participating party is signature generation, so that the participating party whose type of the participating party is signature generation generates the signature based on all the sub-signatures.

[0079] Assume that there are t participating parties participating in signature generation in the signature phase, and the participating parties participating in signature are ; Let be the Lagrange interpolation coefficient. Assume that the participating party is responsible for the synthesis and output of the final signature. Then the collaborative signature generation process is as follows:

[0080] (1) When the signature generation information is obtained, is the message length. For all , the participating party selects a random sub-signature element , generates a sub-signature , and sends the sub-signature to the participating party ; where H is a hash function, and the image set is ;

[0081] (2) The participating party calculates the signature , and outputs the signature Sig.

[0082] It can be understood that if there are three participating parties, all three participating parties calculate their own sub-signatures. Assume that the type of the first participating party is signature generation. Then the second participating party and the third participating party send their own sub-signatures to the first participating party, and then the first participating party generates the signature Sig according to the three sub-signatures.

[0083] Further, after generating the signature based on all the sub-signatures, it further includes: sending the signature to the transformation system, so that the transformation system presents the signature to the client for signature verification; when the instruction indicating that the signature verification is passed returned by the client is obtained, a thread for obtaining the signature transformation instruction is started.

[0084] Specifically, represent the signature Sig as , send the signature to the transformation system, so that the transformation system presents the signature to the client, and represent the public key as The client verifies the equation and to determine if they both hold. If both hold, the signature verification passes. After obtaining the instruction from the client indicating that the signature verification has passed, a thread for obtaining the signature transformation instruction is started.

[0085] Step S14: When the key transformation instruction is obtained, a random polynomial is generated and sent to other parties except itself, so that the other parties calculate the finite field polynomial based on the random polynomial, accumulate the finite field polynomials returned by the other parties, calculate the new private key share, and send the new private key share to the transformation system, so that the transformation system generates a new private key and the corresponding new public key based on all the new private key shares.

[0086] In this embodiment, when the key transformation instruction is obtained, a random polynomial is generated, a random finite field element is selected, an initial random polynomial over the finite field is generated based on the random finite field element, the random polynomial is calculated using the initial random polynomial, and the calculated random polynomial is sent to other parties except itself, so that the other parties calculate the finite field polynomial based on the random polynomial; the finite field polynomials returned by other parties are obtained, all the finite field polynomials are accumulated to obtain an accumulated value; the accumulated value and the private key share corresponding to itself are used to calculate the new private key share to obtain the new private key share, and the new private key share is sent to the transformation system, so that the transformation system generates a new private key and the corresponding new public key based on all the new private key shares.

[0087] This application can achieve key transformation and signature transformation. The key transformation requires the participation of all parties. Let be the Lagrange interpolation coefficients of n parties. The key transformation process is as follows:

[0088] (1) For all , party selects a random finite field element , generates an initial random polynomial over the finite field ; where is a random number in , ; calculates the random polynomial , and sends to party , ; party announces ;

[0089] (2) For all , party Compute to generate a random polynomial over the finite field ; Compute ; and send to the participant ; The participant computes , that is is the accumulation of all polynomial values received by the participant ;

[0090] (3) Compute the new private key share , compute and publish the new public key ; At this time, the transformed new private key is .

[0091] The above key transformation process can be intuitively understood as follows: To transform the private key into the new private key , all participants first select their respective random numbers , calculate the share of using the secret sharing method of polynomial assignment, and then generate the new private key share using the polynomial sharing method of multiplying secret values. Then, send the new private key share to the transformation system, and the transformation system generates the new private key and the corresponding new public key based on the new private key shares of all participants.

[0092] Step S15: When a signature transformation instruction is obtained, generate a new sub-signature based on the original signature corresponding to the signature transformation instruction, determine its own participant type. If its own participant type is non-signature generation, send the new sub-signature to the participant whose participant type is signature generation, so that the participant whose participant type is signature generation can generate a new signature based on all the new sub-signatures.

[0093] In this embodiment, t participants are required to participate in the transformation signature generation in the signature transformation phase. Assume that the participants participating in the transformation signature are ; Let be the Lagrange interpolation coefficients of the t participants; Assume that the participant is responsible for the synthesis and output of the final signature. Then the collaborative transformation signature generation process is as follows:

[0094] (1) For all , the participant selects a random element , represents the existing signature Sig as , and calculates the new sub-signature ; Send to the participant​ ;

[0095] (2) Participants Calculate a new signature , and output the new signature .

[0096] The above signature transformation process can be intuitively understood as follows: In order to transform the signature Sig generated by the old private key into the signature generated by the new private key , each participant needs to select a random number to increase autonomy, and use the share required for the transformation of the new private key to calculate partial signature values on the components of the old signature Sig respectively; finally, the participant uses the partial signature values to merge into the finally transformed new signature .

[0097] This application is based on a threshold secret sharing to collaboratively generate system parameters , the public key pk, and the exponential terms of the private key shares ; in the key transformation stage, the participants collaboratively generate random numbers based on threshold secret sharing and then perform secondary secret sharing to ensure that the transformed key still satisfies the (t, n) threshold characteristic; in the signature transformation stage, the participants each select a random number and use the random numbers collaboratively generated in the key transformation stage to jointly calculate partial signature values. The present invention aims to improve the robustness and resilience of flexible public key signature private keys, is applicable to distributed scenarios, can provide flexible permission control functions, does not rely on components with high overhead such as semi-homomorphic encryption, only requires threshold secret sharing as a basic tool, has low computational overhead, and in the signature generation process, there is no need for each participant to interact and communicate, and the communication overhead is low.

[0098] In this embodiment, the initialization parameters sent by the transformation system are obtained, the initialization parameters are calculated to obtain system sub-parameters, and the system sub-parameters are sent to the transformation system so that the transformation system can generate system parameters by using the threshold secret sharing scheme and based on all the system sub-parameters; the private key shares are calculated for the system parameters and the private key shares are sent to the transformation system so that the transformation system can generate a private key and the corresponding public key based on all the private key shares; when the signature generation information is obtained, a sub-signature is generated, the type of the participating party itself is judged, and if the type of the participating party itself is non-signature generation, the sub-signature is sent to the participating party whose type of the participating party is signature generation so that the participating party whose type of the participating party is signature generation can generate a signature based on all the sub-signatures; when the key transformation instruction is obtained, a random polynomial is generated and the random polynomial is sent to other participating parties except itself so that the other participating parties can calculate the finite field polynomial based on the random polynomial, the finite field polynomials returned by the other participating parties are accumulated and the new private key shares are calculated, and the new private key shares are sent to the transformation system so that the transformation system can generate a new private key and the corresponding new public key based on all the new private key shares; when the signature transformation instruction is obtained, a new sub-signature is generated based on the original signature corresponding to the signature transformation instruction, the type of the participating party itself is judged, and if the type of the participating party itself is non-signature generation, the new sub-signature is sent to the participating party whose type of the participating party is signature generation so that the participating party whose type of the participating party is signature generation can generate a new signature based on all the new sub-signatures. This application calculates the initialization parameters sent by the transformation system to obtain system sub-parameters, generates system parameters, private key shares, a private key and the corresponding public key based on the threshold secret sharing scheme, thresholdizes the single-party signature private key, generates a sub-signature during the signature generation process, and then generates a signature, without the need for each participating party to communicate interactively, with low communication overhead. During the key transformation process, a random polynomial is generated and sent to other participating parties except itself, and the finite field polynomials returned by the other participating parties are accumulated and the new private key shares are calculated so that the transformation system can generate a new private key and the corresponding new public key based on all the new private key shares, which can ensure that the transformed key still satisfies the threshold characteristic. During the signature transformation process, a new sub-signature is generated based on the original signature corresponding to the signature transformation instruction, the type of the participating party itself is judged, and if the type of the participating party itself is non-signature generation, the new sub-signature is sent to the participating party whose type of the participating party is signature generation so that the participating party whose type of the participating party is signature generation can generate a new signature based on all the new sub-signatures. It can be applied to a distributed scenario, can provide a flexible permission control function, and can improve the robustness and robustness of the flexible public key signature private key. This application is applied to any participating party in the transformation system, does not depend on components with high overhead such as homomorphic encryption, and only requires threshold secret sharing as a basic tool, with low calculation overhead.

[0099] SeeFigure 2 As shown in Figure 2 , an embodiment of the present invention discloses a key and flexible public key signature transformation device based on threshold secret sharing, which is applied to any participating party in a transformation system. Specifically, it may include:

[0100] A parameter generation module 11, configured to obtain initialization parameters sent by the transformation system, calculate the system sub-parameters from the initialization parameters, and send the system sub-parameters to the transformation system, so that the transformation system uses the threshold secret sharing scheme and generates system parameters based on all the system sub-parameters;

[0101] A calculation module 12, configured to calculate private key shares from the system parameters and send the private key shares to the transformation system, so that the transformation system generates a private key and a corresponding public key based on all the private key shares;

[0102] A signature generation module 13, configured to generate a sub-signature when signature generation information is obtained, determine its own participating party type. If its own participating party type is non-signature generation, send the sub-signature to the participating party with the signature generation type, so that the participating party with the signature generation type generates a signature based on all the sub-signatures;

[0103] A key transformation module 14, configured to generate a random polynomial when a key transformation instruction is obtained, send the random polynomial to other participating parties except itself, so that the other participating parties calculate a finite field polynomial based on the random polynomial, accumulate the finite field polynomials returned by the other participating parties and calculate new private key shares, and send the new private key shares to the transformation system, so that the transformation system generates a new private key and a corresponding new public key based on all the new private key shares;

[0104] A signature transformation module 15, configured to generate a new sub-signature based on the original signature corresponding to the signature transformation instruction when a signature transformation instruction is obtained, determine its own participating party type. If its own participating party type is non-signature generation, send the new sub-signature to the participating party with the signature generation type, so that the participating party with the signature generation type generates a new signature based on all the new sub-signatures.

[0105] In this embodiment, the initialization parameters sent by the transformation system are obtained, the initialization parameters are calculated to obtain system sub-parameters, and the system sub-parameters are sent to the transformation system so that the transformation system can generate system parameters by using the threshold secret sharing scheme and based on all the system sub-parameters; calculate the private key shares of the system parameters and send the private key shares to the transformation system so that the transformation system can generate a private key and the corresponding public key based on all the private key shares; when the signature generation information is obtained, generate a sub-signature, determine the type of the participating party itself. If the type of the participating party itself is non-signature generation, send the sub-signature to the participating party with the type of signature generation so that the participating party with the type of signature generation can generate a signature based on all the sub-signatures; when the key transformation instruction is obtained, generate a random polynomial and send the random polynomial to other participating parties except itself so that the other participating parties can calculate the finite field polynomial based on the random polynomial, accumulate the finite field polynomials returned by the other participating parties and calculate the new private key shares, and send the new private key shares to the transformation system so that the transformation system can generate a new private key and the corresponding new public key based on all the new private key shares; when the signature transformation instruction is obtained, generate a new sub-signature based on the original signature corresponding to the signature transformation instruction, determine the type of the participating party itself. If the type of the participating party itself is non-signature generation, send the new sub-signature to the participating party with the type of signature generation so that the participating party with the type of signature generation can generate a new signature based on all the new sub-signatures. This application calculates the initialization parameters sent by the transformation system to obtain system sub-parameters, generates system parameters, private key shares, a private key and the corresponding public key based on the threshold secret sharing scheme, threshold the single-party signature private key. During the signature generation process, generate sub-signatures and then generate signatures. There is no need for each participating party to interact and communicate, and the communication overhead is low. During the key transformation process, generate a random polynomial, send the random polynomial to other participating parties except itself, accumulate the finite field polynomials returned by the other participating parties and calculate the new private key shares so that the transformation system can generate a new private key and the corresponding new public key based on all the new private key shares, which can ensure that the transformed key still satisfies the threshold characteristic. During the signature transformation process, generate a new sub-signature based on the original signature corresponding to the signature transformation instruction, determine the type of the participating party itself. If the type of the participating party itself is non-signature generation, send the new sub-signature to the participating party with the type of signature generation so that the participating party with the type of signature generation can generate a new signature based on all the new sub-signatures. It can be applied to any participating party in the transformation system, does not rely on components with high overhead such as homomorphic encryption, and only requires threshold secret sharing as a basic tool, with low calculation overhead.

[0106] In some specific embodiments, the parameter generation module 11 may specifically include:

[0107] An initialization parameter generation module, configured to obtain initialization parameters including large prime numbers, cyclic groups, and bilinear pair mappings generated based on security parameters sent by the transformation system; the cyclic groups include a first cyclic group, a second cyclic group, and a third cyclic group;

[0108] A system sub-parameter calculation module, configured to select random system calculation elements, and calculate the random system calculation elements, a first generator corresponding to the first cyclic group, and a second generator corresponding to the second cyclic group to obtain a first system sub-parameter and a second system sub-parameter.

[0109] In some specific embodiments, the first system sub-parameter is:

[0110] ;

[0111] Wherein, is a random system calculation element, and , , is a non-zero integer domain, n is the number of participants, is the first generator corresponding to the first cyclic group, is the first system sub-parameter;

[0112] The second system sub-parameter is:

[0113] ;

[0114] Wherein, is the second generator corresponding to the second cyclic group, is the second system sub-parameter;

[0115] Correspondingly, the system parameters include a first system parameter and a second system parameter;

[0116] The first system parameter is:

[0117] ;

[0118] Wherein, is the product symbol;

[0119] The second system parameter is:

[0120] .

[0121] In some specific embodiments, the calculation module 12 may specifically include:

[0122] The private key share polynomial calculation module is used to select random polynomial elements and calculate the first private key share polynomial and the second private key share polynomial based on the random polynomial elements;

[0123] The private key share polynomial sending module is used to send the second private key share polynomial to other participants except itself and obtain the third private key share polynomial sent by the other participants;

[0124] The private key share calculation module is used to calculate the private key share by using the first private key share polynomial and the third private key share polynomial.

[0125] In some specific embodiments, the signature generation module 13 may specifically include:

[0126] The sub-signature generation module is used to select random sub-signature elements when obtaining signature generation information, and generate a sub-signature by using the random sub-signature elements, the private key share, the Lagrange interpolation coefficient, and the initialization parameter;

[0127] The signature generation module is used to judge its own participant type. If its own participant type is signature generation, it directly obtains the sub-signatures sent by other participants except itself and generates a signature based on all the sub-signatures.

[0128] In some specific embodiments, the signature generation module 13 may specifically include:

[0129] The signature verification module is used to send the signature to the transformation system so that the transformation system can present the signature to the client for signature verification;

[0130] The thread start module is used to start a thread for obtaining signature transformation instructions after obtaining an instruction returned by the client indicating that the signature verification is passed.

[0131] In some specific embodiments, the key transformation module 14 may specifically include:

[0132] The random polynomial sending module is used to select random finite field elements, generate an initial random polynomial over the finite field based on the random finite field elements, calculate a random polynomial by using the initial random polynomial, and send the calculated random polynomial to other participants except itself so that the other participants can calculate a finite field polynomial based on the random polynomial;

[0133] The accumulation module is used to obtain each of the finite field polynomials returned by other participants, accumulate all the finite field polynomials, and obtain an accumulated value;

[0134] A new private key share calculation module is configured to calculate a new private key share based on the accumulated value and its corresponding private key share, so as to obtain a new private key share.

[0135] Figure 3 FIG. 4 is a schematic structural diagram of an electronic device provided by an embodiment of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. Wherein, the memory 22 is configured to store a computer program, and the computer program is loaded and executed by the processor 21 to implement the relevant steps in the method for key and flexible public key signature transformation based on threshold secret sharing executed by the electronic device disclosed in any of the foregoing embodiments.

[0136] In this embodiment, the power supply 23 is configured to provide a working voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows is any communication protocol applicable to the technical solution of the present application, and no specific limitation is imposed thereon here; the input / output interface 25 is configured to obtain external input data or output data to the outside, and the specific interface type thereof can be selected according to specific application requirements, and no specific limitation is made here.

[0137] In addition, as a carrier for resource storage, the memory 22 may be a read-only memory, a random access memory, a disk, or an optical disc, etc., and the resources stored thereon include an operating system 221, a computer program 222, and data 223, etc., and the storage method may be temporary storage or permanent storage.

[0138] Wherein, the operating system 221 is configured to manage and control each hardware device on the electronic device 20 and the computer program 222, so as to implement the operation and processing of the data 223 in the memory 22 by the processor 21, and it may be Windows, Unix, Linux, etc. The computer program 222 may further include a computer program capable of completing other specific tasks in addition to the computer program capable of implementing the method for key and flexible public key signature transformation based on threshold secret sharing executed by the electronic device 20 disclosed in any of the foregoing embodiments. The data 223 may include not only data transmitted from external devices received by the key and flexible public key signature transformation device based on threshold secret sharing, but also data collected by its own input / output interface 25, etc.

[0139] The steps of the methods or algorithms described in combination with the embodiments disclosed in this article can be implemented directly by hardware, software modules executed by a processor, or a combination of both. The software modules can be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the technical field.

[0140] Furthermore, an embodiment of the present application also discloses a computer-readable storage medium. When a computer program stored in the storage medium is loaded and executed by a processor, it implements the steps of the key and flexible public key signature transformation method based on threshold secret sharing disclosed in any of the foregoing embodiments.

[0141] Finally, it should also be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the existence of additional identical elements in the process, method, article or device comprising the element.

[0142] The above has introduced in detail a key and flexible public key signature transformation method, device, equipment and storage medium based on threshold secret sharing provided by the present invention. Specific examples are used in this article to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present invention.

Claims

1. A key and flexible public key signature transformation method based on threshold secret sharing, characterized in that Applied to any participant in the transformation system, including: Obtain the initialization parameters sent by the transformation system, calculate the initialization parameters to obtain system sub-parameters, and send the system sub-parameters to the transformation system so that the transformation system can generate system parameters using the threshold secret sharing scheme and based on all the system sub-parameters; Calculate the private key shares for the system parameters and send the private key shares to the transformation system so that the transformation system can generate a private key and the corresponding public key based on all the private key shares; When obtaining signature generation information, generate a sub-signature, determine its own participant type. If its own participant type is non-signature generation, send the sub-signature to the participant with the signature generation participant type so that the participant with the signature generation participant type can generate a signature based on all the sub-signatures; When obtaining a key transformation instruction, generate a random polynomial, send the random polynomial to other participants except itself so that the other participants can calculate a finite field polynomial based on the random polynomial, accumulate the finite field polynomials returned by the other participants and calculate new private key shares, and send the new private key shares to the transformation system so that the transformation system can generate a new private key and the corresponding new public key based on all the new private key shares; When obtaining a signature transformation instruction, generate a new sub-signature based on the original signature corresponding to the signature transformation instruction, determine its own participant type. If its own participant type is non-signature generation, send the new sub-signature to the participant with the signature generation participant type so that the participant with the signature generation participant type can generate a new signature based on all the new sub-signatures.

2. The method for key and flexible public key signature transformation based on threshold secret sharing according to claim 1, characterized in that The obtaining the initialization parameters sent by the transformation system and calculating the initialization parameters to obtain system sub-parameters includes: Obtain the initialization parameters sent by the transformation system, which are generated based on security parameters and include large prime numbers, cyclic groups, and bilinear pairings; the cyclic groups include a first cyclic group, a second cyclic group, and a third cyclic group; Select random system calculation elements, and calculate the first system sub-parameter and the second system sub-parameter by calculating the random system calculation elements, the first generator corresponding to the first cyclic group, and the second generator corresponding to the second cyclic group.

3. The method for key and flexible public key signature transformation based on threshold secret sharing according to claim 2, characterized in that, The first system sub-parameter is: ; Among them, is a random system calculation element, and , , is a non-zero integer domain, n is the number of participants, is the first generator corresponding to the first cyclic group, is the first system sub-parameter; The second system sub-parameter is: ; Among them, is the second generator corresponding to the second cyclic group, is the second system sub-parameter; Correspondingly, the system parameters include a first system parameter and a second system parameter; The first system parameter is: ; Among them, is the product symbol; the second system parameter is: 。 4. The method for key and flexible public key signature transformation based on threshold secret sharing according to claim 1, wherein The calculating the private key shares for the system parameters includes: Select random polynomial elements, and calculate a first private key share polynomial and a second private key share polynomial based on the random polynomial elements; Send the second private key share polynomial to other participants except itself, and obtain the third private key share polynomial sent by the other participants; Calculate the private key shares using the first private key share polynomial and the third private key share polynomial.

5. The key and flexible public key signature transformation method based on threshold secret sharing according to claim 1, characterized in that The when obtaining signature generation information, generating a sub-signature and determining its own participant type includes: When the signature generation information is obtained, select random sub-signature elements, and generate a sub-signature by using the random sub-signature elements, the private key share, the Lagrange interpolation coefficient, and the initialization parameter; Determine the type of the participating party itself. If the type of the participating party itself is signature generation, directly obtain the sub-signatures sent by other participating parties except itself, and generate a signature based on all the sub-signatures.

6. The method for key and flexible public key signature transformation based on threshold secret sharing according to claim 5, wherein After generating the signature based on all the sub-signatures, it further includes: Send the signature to the transformation system so that the transformation system can present the signature to the client for signature verification; When the instruction indicating that the signature verification is passed returned by the client is obtained, start a thread for obtaining the signature transformation instruction.

7. The method for key and flexible public key signature transformation based on threshold secret sharing according to any one of claims 1 to 6, characterized in that The sending the random polynomial to other participating parties except itself so that the other participating parties calculate the finite field polynomial based on the random polynomial, and performing accumulation and new private key share calculation on the finite field polynomials returned by the other participating parties includes: Select random finite field elements, generate an initial random polynomial over the finite field based on the random finite field elements, calculate a random polynomial by using the initial random polynomial, and send the calculated random polynomial to other participating parties except itself so that the other participating parties calculate the finite field polynomial based on the random polynomial; Obtain each of the finite field polynomials returned by other participating parties, and perform accumulation on all the finite field polynomials to obtain an accumulated value; Perform new private key share calculation on the accumulated value and the private key share corresponding to itself to obtain a new private key share.

8. A key and flexible public key signature transformation device based on threshold secret sharing, characterized in that, Applied to any participating party in the transformation system, it includes: A parameter generation module, configured to obtain the initialization parameter sent by the transformation system, calculate the system sub-parameter from the initialization parameter, and send the system sub-parameter to the transformation system so that the transformation system can generate the system parameter by using the threshold secret sharing scheme and based on all the system sub-parameters; A calculation module, configured to calculate the private key share from the system parameter, and send the private key share to the transformation system so that the transformation system can generate the private key and the corresponding public key based on all the private key shares; A signature generation module, configured to generate a sub-signature when the signature generation information is obtained, determine the type of the participating party itself. If the type of the participating party itself is non-signature generation, send the sub-signature to the participating party whose type is signature generation so that the participating party whose type is signature generation can generate a signature based on all the sub-signatures; A key transformation module, configured to generate a random polynomial when the key transformation instruction is obtained, send the random polynomial to other participating parties except itself so that the other participating parties calculate the finite field polynomial based on the random polynomial, perform accumulation and new private key share calculation on the finite field polynomials returned by the other participating parties, and send the new private key share to the transformation system so that the transformation system can generate a new private key and the corresponding new public key based on all the new private key shares; A signature transformation module, which is configured to, when a signature transformation instruction is obtained, generate a new sub-signature based on the original signature corresponding to the signature transformation instruction, determine its own participant type, and if its own participant type is non-signature generation, send the new sub-signature to a participant whose participant type is signature generation, so that the participant whose participant type is signature generation can generate a new signature based on all the new sub-signatures.

9. An electronic device, characterized in that, It includes: A memory for storing a computer program; A processor for executing the computer program to implement the key and flexible public key signature transformation method based on threshold secret sharing as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that For storing a computer program; wherein, when the computer program is executed by the processor, it implements the key and flexible public key signature transformation method based on threshold secret sharing as described in any one of claims 1 to 7.

Citation Information

Cited By

  • Quantum security verifiable secret sharing method and device, equipment and storage medium

    CN121396443A